Insecure file upload In codeigniter4/framework
Description
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
Impact
This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.
Applications are impacted when they:
validate uploads using is_image or mime_in without an independent safe extension check, such as ext_in on patched versions
save uploaded files using the client-supplied filename
place uploads in a web-accessible directory where PHP files can execute
Patches
Upgrade to v4.7.4 or later.
Workarounds
Save uploads outside the public web root, preferably under writable/uploads.
Use $file->store() or $file->move($path, $file->getRandomName()) instead of preserving the original client filename.
Disable script execution in any public upload directory.
Manually verify the client filename extension before moving the file.
For image uploads, reject files when $file->getClientExtension() is not an allowed image extension.
For exact MIME-type validation, reject files when $file->getClientExtension() does not match $file->guessExtension().
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.7.4 |
Aliases
References